Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
Showing 6,481 - 6,500 of 13,907 CVEs
CVE-2025-65132 MEDIUM - 6.1

alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which allows an attacker to inject and execute arbitrary JavaScript via the room_id GET parameter.

Published: Apr 14, 2026
Source: NVD
CVE-2025-61886 MEDIUM - 5.4

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.

Vendor: Fortinet
Product: FortiSandbox PaaS, FortiSandbox
Published: Apr 14, 2026
Source: NVD
CVE-2025-61624 MEDIUM - 6.0

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all vers...

Vendor: Fortinet
Product: FortiOS, FortiProxy, FortiSwitchManager, FortiPAM
Published: Apr 14, 2026
Source: NVD
CVE-2025-59809 MEDIUM - 4.3

A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6....

Vendor: Fortinet
Product: FortiSOAR on-premise, FortiSOAR PaaS
Published: Apr 14, 2026
Source: NVD
CVE-2025-53847 MEDIUM - 6.5

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or comman...

Vendor: Fortinet
Product: FortiOS
Published: Apr 14, 2026
Source: NVD
CVE-2024-23104 MEDIUM - 5.4

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at leas...

Vendor: Fortinet
Product: FortiVoice, FortiNDR
Published: Apr 14, 2026
Source: NVD
CVE-2026-4914 MEDIUM - 5.4

Stored XSSĀ inĀ IvantiĀ N-ITSMĀ beforeĀ version 2025.4Ā allows aĀ remoteĀ authenticatedĀ attacker toĀ obtain limited information from other user sessions.Ā User interaction is required.

Published: Apr 14, 2026
Source: NVD
CVE-2026-4913 MEDIUM - 5.7

Improper protection of an alternate pathĀ inĀ IvantiĀ N-ITSMĀ beforeĀ version 2025.4Ā allows aĀ remote authenticatedĀ attacker toĀ retain access when their account has beenĀ disabled.

Published: Apr 14, 2026
Source: NVD
CVE-2026-37980 MEDIUM - 6.9

A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed in...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: Apr 14, 2026
Source: NVD
CVE-2026-30480 MEDIUM - 6.5

A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.

Published: Apr 14, 2026
Source: NVD
CVE-2025-69993 MEDIUM - 6.1

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x o...

Vendor: leafletjs
Product: leaflet
Published: Apr 14, 2026
Source: NVD
CVE-2025-69893 MEDIUM - 4.6

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant time...

Published: Apr 14, 2026
Source: NVD
CVE-2026-24069 MEDIUM - 5.4

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

Vendor: Kiuwan
Product: SAST
Published: Apr 14, 2026
Source: NVD
CVE-2026-4109 MEDIUM - 4.3

The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible f...

Published: Apr 14, 2026
Source: NVD
CVE-2026-33929 MEDIUM - 4.3

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are recommended to update to version...

Vendor: Apache Software Foundation
Product: Apache PDFBox Examples
Published: Apr 14, 2026
Source: NVD
CVE-2026-31924 MEDIUM - 5.3

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

Vendor: Apache Software Foundation
Product: Apache APISIX
Published: Apr 14, 2026
Source: NVD
CVE-2026-2582 MEDIUM - 6.5

The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_holder' parameter in all versions up to, and including, 3.20.5. This is due to the software allowing users to execute an action that does not properly validate a value before...

Published: Apr 14, 2026
Source: NVD
CVE-2026-4479 MEDIUM - 4.4

The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Published: Apr 14, 2026
Source: NVD
CVE-2026-4059 MEDIUM - 6.4

The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shortcode's button_text attribute in all versions up to, and including, 3.3.5. This is due to insufficient input sanitization and missing output escaping on user-supplied shortcod...

Published: Apr 14, 2026
Source: NVD
CVE-2026-1607 MEDIUM - 6.4

The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `surbma-bookingcom` shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos...

Published: Apr 14, 2026
Source: NVD